[JIRA] (JENKINS-24548) Write a plugin that adds HTTP Strict-Transport-Security header for better security

4 views
Skip to first unread message

vermyndax@gmail.com (JIRA)

unread,
Aug 6, 2019, 7:36:02 PM8/6/19
to jenkinsc...@googlegroups.com
Jason Miller commented on New Feature JENKINS-24548
 
Re: Write a plugin that adds HTTP Strict-Transport-Security header for better security

Kalle Niemitalo for my use case, no.

I am using jenkins:lts on an Amazon Web Services ECS cluster backed by Elastic File System (NFS) for Jenkins' file system. It is fronted by an AWS load balancer. We have a requirement to return the HSTS header. I tried loading the HSTS filter plugin and it crashed the container. I had to get into the file system to remove the plugin manually for it to restart.

This is a fairly common requirement in many IT situations. I'm faced with either increasing complexity in the architecture to meet this requirement or modify the container to somehow get the servlet to return this header. A working plugin would be nice, or just an option. I visited the github page for the plugin and it appears that project is no longer maintained.

Add Comment Add Comment
 
This message was sent by Atlassian Jira (v7.11.2#711002-sha1:fdc329d)
Reply all
Reply to author
Forward
0 new messages